CWE-67 · 7 records
Improper Handling of Windows Device Names
CVEs in this class
7 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
27Monitor | CVE-2026-17545No exploit | PHP on Windows: Reserved Device Names Are Not Rejected Before File/Stream I/O which can cause DoSphp group · php · CWE-67 | Medium6.9 | — | 0.3% | 4 days ago |
25Monitor | CVE-2026-27199Proof of concept | Werkzeug safe_join() allows Windows special device namespalletsprojects · werkzeug · CWE-67 | Medium6.3 | — | 0.5% | Feb 21, 2026 |
25Monitor | CVE-2025-66221No exploit | Werkzeug safe_join() allows Windows special device namespalletsprojects · werkzeug · CWE-67 | Medium6.3 | — | 0.5% | Nov 28, 2025 |
25Monitor | CVE-2026-21860No exploit | Werkzeug safe_join() allows Windows special device names with compound extensionspalletsprojects · werkzeug · CWE-67 | Medium6.3 | — | 0.5% | Jan 8, 2026 |
25Monitor | CVE-2026-102598No exploit | Werkzeug safe_join() allows Windows special device namespallets · werkzeug · CWE-67 | Medium6.3 | — | — | 1 day ago |
21Monitor | CVE-2024-35197No exploit | gix refs and paths with reserved Windows device names access the devicesbyron · gitoxide · CWE-67 | Medium5.4 | — | 0.4% | May 23, 2024 |
9Monitor | CVE-2024-51745No exploit | Wasmtime doesn't fully sandbox all the Windows device filenamesbytecodealliance · wasmtime · CWE-67 | Low2.3 | — | 0.8% | Nov 5, 2024 |
- CVE-2026-1754527Monitor
PHP on Windows: Reserved Device Names Are Not Rejected Before File/Stream I/O which can cause DoS
MediumCVSS 6.9No exploitEPSS 0%php group · php4 days ago
- CVE-2026-2719925Monitor
Werkzeug safe_join() allows Windows special device names
MediumCVSS 6.3Proof of conceptEPSS 1%palletsprojects · werkzeugFeb 21, 2026
- CVE-2025-6622125Monitor
Werkzeug safe_join() allows Windows special device names
MediumCVSS 6.3No exploitEPSS 1%palletsprojects · werkzeugNov 28, 2025
- CVE-2026-2186025Monitor
Werkzeug safe_join() allows Windows special device names with compound extensions
MediumCVSS 6.3No exploitEPSS 0%palletsprojects · werkzeugJan 8, 2026
- CVE-2026-10259825Monitor
Werkzeug safe_join() allows Windows special device names
MediumCVSS 6.3No exploitpallets · werkzeug1 day ago
- CVE-2024-3519721Monitor
gix refs and paths with reserved Windows device names access the devices
MediumCVSS 5.4No exploitEPSS 0%byron · gitoxideMay 23, 2024
- CVE-2024-517459Monitor
Wasmtime doesn't fully sandbox all the Windows device filenames
LowCVSS 2.3No exploitEPSS 1%bytecodealliance · wasmtimeNov 5, 2024